VeUP
← All case studies
Security · Security Hub remediation
An AI meeting-intelligence SaaS companyIdentity protected

CLIPr: remediating a 13-account Control Tower landing zone for a clean security audit

Well-Architected ReviewLanding zone remediationPreventive controlsMulti-account segmentationCentralized workforce identityCentralized immutable audit loggingAudit-readiness evidence packDay-2 runbooks & team enablementHigh-risk-issue remediation roadmapResilience-gap assessment (RTO/RPO)Observability-gap assessmentAdvisory
13/13
accounts validated and governed in Control Tower
Audit-ready
complete evidence set for the third-party audit
Built to carry
SOC 2, PCI-DSS, and HIPAA work ahead
AWS Security HubAWS Organizations (SCPs)AWS IAM Identity CenterAWS CloudTrail

Facing a third-party security audit, this AI SaaS company’s 13-account organization carried a drifted, partial security baseline. VeUP delivered the compliance-and-privacy remediation that closed the gap: AWS Security Hub enabled organization-wide with the AWS Foundational Security Best Practices and CIS standards, SCP guardrails hardened, CloudTrail logging remediated, and IAM Identity Center reconciled — a posture the audit could measure rather than take on faith.

The challenge

An AI meeting-intelligence product processes some of the most sensitive data a company produces — its conversations — so customers and their security teams ask hard questions, and a third-party audit turns those questions into pass/fail findings. The organization’s security tooling had drifted into partial coverage: standards enabled in some accounts, logging with gaps, identity assignments accumulated rather than designed, and guardrails weaker than the landing zone intended. Individually minor; collectively, exactly the picture an auditor writes up. The estate needed its security baseline restored to organization scope and proven there.

The solution

Following a hands-on assessment in March 2026, VeUP delivered the Phase 1 audit-readiness remediation. AWS Security Hub was enabled organization-wide with the FSBP and CIS AWS Foundations standards, converting the security baseline from tribal knowledge into continuously scored checks across all 13 accounts. CloudTrail logging was remediated so the audit trail is complete and protected; IAM Identity Center was reconciled so workforce access matches design rather than history; Service Control Policy guardrails were hardened at the organization layer; organizational AWS Backup policies were deployed; and Control Tower enrollments and AWS Config recording were validated in every member account, with StackSet drift checked. The engagement closed with the remediation, validation, and documentation package the customer needed to face a governance or compliance audit — the security work and the evidence of the security work, delivered together.

Production outcomes

KPIResult
Standards coverageSecurity Hub enabled organization-wide with FSBP + CIS from a drifted, partial baseline — the security posture of all 13 accounts scored continuously against published standards.
Controls remediatedCloudTrail logging fixed, IAM Identity Center reconciled, SCP guardrails hardened, org-wide Backup policies deployed — the identity, logging, and policy layers brought back to intent.
Verified foundation13/13 Control Tower enrollments validated and Config recording verified in every account — remediation claims backed by per-account evidence, packaged for the audit.
Lessons & continuationAudit readiness is a security outcome, not a paperwork exercise: enable standards at organization scope so coverage cannot silently fragment, and treat the evidence trail (Config, CloudTrail) as a control in its own right.
AWS services in production
AWS Security Hub (FSBP + CIS)AWS Organizations (SCP guardrails)AWS Control TowerAWS CloudTrailAWS IAM Identity CenterAWS ConfigAWS Backup (org policies)AWS IAM